Senior Manager DevSecOps Application Security Engineering
CVS HealthAbout the role
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world. Anchored in our brand — with heart at its center — our purpose sends a personal message that how we deliver our services is just as important as what we deliver.
Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable.
Who You Are
· Deeply experienced in coding with a nuanced understanding of Object-Oriented and Functional programming concepts, capable of writing and reviewing code across multiple languages and paradigms.
· Highly passionate about building and operating secure, reliable systems at scale, with a proven track record in similar environments.
· Demonstrated ability to innovate and automate security processes and functions through code, enhancing efficiency and effectiveness.
· Demonstrated managerial skills with the ability to lead, mentor, and develop a diverse security engineering team, fostering an inclusive culture of continuous learning, excellence, and innovation.
· Strong technical expertise with Application, Cloud, Data, and Network Security best practices.
· Strong technical expertise with multi-cloud environments, including container/serverless and other microservice architectures.
· Strong technical expertise with older technology stacks, including mainframes and monolithic architectures.
· Strong technical expertise with SDLC, CI/CD tools, and Deployment Automation.
· Strong technical expertise with operating security for Windows Server and Linux Server systems.
· Strong technical expertise with configuration management, version control, and DevOps operational support.
· Strong experience with implementing security measures for both applications and data, with an understanding of the unique security requirements of data warehouse technologies such as Snowflake.
Role Responsibilities
Development & Enforcement
· Develop and enforce engineering security policies and standards.
· Develop and enforce data security policies and standards.
· Drive security awareness across the organization.
· Oversee the development and enforcement of comprehensive security policies and standards, ensuring advanced security practices are integrated throughout the software development lifecycle to mitigate risks and maintain alignment with industry-leading security protocols. Facilitate collaboration between security, development, and operations teams to foster a unified approach to secure software development.
· Regularly review and update security policies and standards to reflect evolving threat landscapes and technological advancements, embedding a culture of continuous improvement within the team.
Collaboration & Expertise
· Build and maintain strong relationships with product management, engineering leaders, and other key stakeholders to seamlessly integrate security considerations into product development lifecycles and operational processes.
· Serve as a key security figure, orchestrating the integration of secure engineering practices across the organization and ensuring alignment with business objectives through strategic communication with senior management and other stakeholders.
Analysis & Configuration
· Analyze, develop, and configure security solutions across multi-cloud, on-premises, and colocation environments, ensuring application security, integrity, confidentiality, and availability of data.
· Lead security testing, vulnerability analysis, and documentation.
· Spearhead the evaluation and strategic deployment of cutting-edge security solutions, emphasizing scalability, performance, and adaptability, to fortify the organization's defense against evolving threats.
· Enhance and maintain a dynamic security architecture framework that empowers project teams to develop secure solutions, fostering agility and innovation within secure boundaries, thus aligning security measures with business objectives.
Operational Support
· Participate in operational on-call duties to support a 24/7 infrastructure across multiple regions and environments (cloud, on-premises, colocation).
· Manage the security incident response team, ensuring rapid and effective handling of all security incidents, and leverage these experiences to develop and refine a resilient incident response strategy.
· Implement a metrics-driven approach to security o
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s